Privacy Policy

Preamble

Introduction

This privacy policy explains what types of personal data we process, for what purposes, and to what extent. The privacy policy applies to all processing of personal data by us, both in the provision of our services and in particular on our websites, in mobile applications, and within external online presences such as our social media profiles (collectively referred to as “Online Services”).

The terms used are not gender-specific.

Last Updated: June 12, 2026


Responsible Party

Provider

discoveriesofamom.com

Johanna Kazungu
Florentiner Str. 9
70619 Stuttgart

Authorized Representative: Johanna Kazungu

Email: johanna@discoveriesofamom.com

Imprint: discoveriesofamom.com/de/impressum


Overview of Data Processing

Types of Data Processed

  • Personal information (name, address, contact details, customer number, etc.)
  • Payment data
  • Contact data
  • Content data
  • Contract data
  • Usage data
  • Meta, communication and procedural data
  • Log data

Categories of Affected Persons

  • Service recipients and clients
  • Interested parties
  • Communication partners
  • Users
  • Business and contract partners
  • Education and course participants

Purposes of Processing

  • Performance of contractual services and fulfillment of contractual obligations
  • Communication
  • Security measures
  • Direct marketing
  • Reach measurement
  • Tracking
  • Office and organizational procedures
  • Target group formation
  • Organization and administrative procedures
  • Feedback
  • Marketing
  • User profiles with user-related information
  • Provision of our online services and user-friendliness
  • IT infrastructure
  • Public relations
  • Sales promotion
  • Business processes and business procedures

Legal Basis under GDPR

Data Protection Basis

We process personal data based on the following legal bases under GDPR:

  • Consent (Article 6(1)(a) GDPR) – The affected person has given their consent to the processing of their personal data for a specific purpose or specific purposes.
  • Contract Performance and Pre-contractual Requests (Article 6(1)(b) GDPR) – Processing is necessary to fulfill a contract to which the affected person is a party or to carry out pre-contractual measures requested by the affected person.
  • Legal Obligation (Article 6(1)(c) GDPR) – Processing is necessary to comply with a legal obligation to which we are subject.
  • Legitimate Interests (Article 6(1)(f) GDPR) – Processing is necessary to protect the legitimate interests of us or a third party, provided that the interests, fundamental rights, and fundamental freedoms of the affected person do not take precedence.

German Data Protection Laws

In addition to GDPR, German data protection laws apply, particularly the Federal Data Protection Act (BDSG). The BDSG contains special regulations regarding the right to information, right to deletion, right to object, processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making including profiling. State data protection laws may also apply.


Security Measures

Data Protection Standards

We implement appropriate technical and organizational measures in accordance with legal requirements, considering the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of the processing to ensure adequate protection proportionate to the risk.

Specific Measures

These measures include:

  • Securing confidentiality, integrity, and availability of data through control of physical and electronic access to data
  • Data handling security through controlled input, transmission, storage, availability, and separation
  • Procedures for exercising affected person rights and responding to data breaches
  • Privacy by design principles in hardware, software, and procedure selection
  • Data-protective default settings

TLS/SSL Encryption

We use TLS/SSL encryption technology to protect user data transmitted through our online services. These technologies encrypt information exchanged between the website/app and the user’s browser, protecting data from unauthorized access. When a website is secured by an SSL/TLS certificate, this is indicated by “HTTPS” in the URL.


General Information on Data Storage and Deletion

Deletion Principles

We delete personal data in accordance with legal requirements once the underlying consents are withdrawn or no further legal basis for processing exists. We retain data when legal obligations or special interests require longer storage or archiving.

Data Subject to Extended Storage

Data that must be retained for commercial or tax reasons, or that is necessary for legal proceedings or to protect the rights of others, must be archived accordingly.

Storage Periods under German Law

  • 10 years – Retention period for books, records, annual financial statements, inventories, situation reports, and opening balance sheets (§ 147 Abs. 1 Nr. 1 AO, etc.)
  • 8 years – Booking documents such as invoices and cost documents (§ 147 Abs. 1 Nr. 4, 4a AO, etc.)
  • 6 years – Other business documents such as received business letters, copies of sent business letters, and other documents relevant for taxation (§ 147 Abs. 1 Nr. 2, 3, 5 AO, etc.)
  • 3 years – Data required to handle potential warranty, damage compensation, or similar contractual claims, based on standard legal limitation periods (§§ 195, 199 BGB)

Calculation of Retention Periods

If a deadline does not begin on a specific date and is at least one year long, it automatically begins at the end of the calendar year in which the triggering event occurred. For ongoing contracts, the triggering event is the effective date of termination or other end of the contract.


Rights of Affected Persons

Your Rights under GDPR

As an affected person under GDPR, you have the following rights:

  • Right to Object – You may object at any time to processing of your data for legitimate reasons, particularly where processing is based on Article 6(1)(e) or (f) GDPR. You may also object to direct marketing and related profiling at any time.
  • Right to Withdraw Consent – You may revoke any given consent at any time.
  • Right to Information/Access – You may request confirmation of whether your data is being processed and receive information about that data and copies of the data in accordance with legal requirements.
  • Right to Correction – You may request that incomplete data be completed or incorrect data be corrected.
  • Right to Deletion and Restriction of Processing – You may request that your data be deleted immediately or, alternatively, that processing of your data be restricted, in accordance with legal requirements.
  • Right to Data Portability – You may receive your data in a structured, commonly used, and machine-readable format or request its transmission to another responsible party.
  • Right to Lodge a Complaint – You have the right to file a complaint with a supervisory authority, particularly in the member state of your habitual residence, workplace, or place of alleged violation, if you believe we are processing your personal data in violation of GDPR.

Business Services

Contract and Business Partner Data

We process data from our contract and business partners (customers and interested parties collectively called “Contract Partners”) as part of contractual and similar legal relationships, associated measures, and communication with these partners.

Processing and Purposes

We use this data to:

  • Fulfill our contractual obligations
  • Provide agreed services
  • Handle warranty and performance issues
  • Protect our rights and interests
  • Manage administration related to contractual obligations
  • Ensure proper business management and security
  • Coordinate with service providers, banks, tax and legal advisors, and payment service providers

We share partner data with third parties only to the extent necessary for these purposes or to comply with legal obligations.

Data Disclosure

We notify Contract Partners before or during data collection which information is required and mark mandatory fields appropriately (e.g., through colors or symbols such as asterisks).

Retention and Deletion

We delete data after expiration of legal warranty and comparable obligations (generally after four years), unless data is stored in a customer account or must be retained for legal archiving purposes (such as for tax purposes, typically ten years). Data disclosed to us as part of an assignment is deleted according to the contractual terms and generally after the assignment ends.

Data Types and Legal Basis

AspectDetails
Data TypesPersonal information (name, address, contact details, customer number); Payment data (bank details, invoices, payment history); Contact data (postal/email addresses, phone numbers); Contract data (subject matter, duration, customer category)
Affected PersonsService recipients and clients; Interested parties; Business and contract partners; Education and course participants
Processing PurposesContract performance and fulfillment; Communication; Office and organizational procedures; Business processes and procedures
RetentionPer “General Information on Data Storage and Deletion” section
Legal BasisContract performance and pre-contractual requests (Article 6(1)(b) GDPR); Legal obligation (Article 6(1)(c) GDPR); Legitimate interests (Article 6(1)(f) GDPR)

Education and Training Services

We process data for course and training participants to deliver educational services. Data is processed according to the underlying contract and training relationship. Processing includes performance evaluation and evaluation of instruction.

We may process special categories of data, including health information and data revealing ethnic origin, political opinions, or religious/ideological beliefs. We obtain explicit consent where required and only process these special categories where necessary to provide training services or for health protection, social protection, or protection of vital interests.

Legal Basis: Contract performance and pre-contractual requests (Article 6(1)(b) GDPR)

Event Management

We process participant data to enable participation in events and activities we offer or organize and to provide associated services or activities.

When we process health-related data, religious, political, or other special categories of data in this context, processing occurs through public engagement (e.g., at thematically-oriented events) or serves health protection, security, or occurs with the affected person’s consent.

Required information is marked as such in the order, booking, or comparable contract and includes information necessary for service delivery and billing as well as contact information for follow-up. Where we access information of end customers, employees, or other persons, we process it in accordance with legal and contractual requirements.

Legal Basis: Contract performance and pre-contractual requests (Article 6(1)(b) GDPR)


Provision of Online Services and Web Hosting

Processing for Service Delivery

We process user data to provide our online services. For this purpose, we process the user’s IP address, which is necessary to transmit our content and functionality to the user’s browser or device.

AspectDetails
Data TypesUsage data (page views, time spent, click paths, usage intensity/frequency, device types, operating systems, content/function interactions); Meta, communication, and procedural data (IP addresses, timestamps, identification numbers, involved persons); Log data (logins, data access, access times); Content data (text/image messages and posts and related information such as authorship and creation time)
Affected PersonsUsers (website visitors, online service users)
Processing PurposesProvision of online services and user-friendliness; IT infrastructure (operation of information systems and technical devices); Security measures
RetentionPer “General Information on Data Storage and Deletion” section
Legal BasisLegitimate interests (Article 6(1)(f) GDPR)

Web Hosting on Rented Server Space

We use server space, computing capacity, and software rented from or obtained from a web hosting provider to provide our online services.

Legal Basis: Legitimate interests (Article 6(1)(f) GDPR)

Collection of Access Data and Log Files

Access to our online services is logged in “server log files,” which may include:

  • Website and file addresses and names
  • Date and time of access
  • Data transferred
  • Successful retrieval notification
  • Browser type and version
  • User’s operating system
  • Referrer URL (previously visited page)
  • IP address and requesting provider

Server logs are used for security purposes (preventing server overload and DDoS attacks) and to ensure server utilization and stability.

Legal Basis: Legitimate interests (Article 6(1)(f) GDPR)

Data Deletion: Log information is stored for a maximum of 30 days and then deleted or anonymized. Data required for evidence purposes is excluded from deletion until the relevant incident is fully resolved.

Email Transmission and Hosting

Our web hosting services include email sending, receiving, and storage. For these purposes, we process recipient and sender addresses and other email transmission information (such as involved providers) and email content.

This data is also processed for SPAM detection purposes. Please note that emails are generally not encrypted during internet transmission. Typically, emails are encrypted in transit but not on the servers from which they are sent and received (unless end-to-end encryption is used). We therefore cannot be responsible for the transmission path of emails between sender and our server.

Legal Basis: Legitimate interests (Article 6(1)(f) GDPR)

WordPress.com

We use WordPress.com for hosting and website/blog creation and operation.

AspectDetails
Service ProviderAut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland
Legal BasisLegitimate interests (Article 6(1)(f) GDPR)
Websitehttps://wordpress.com
Privacy Policyhttps://automattic.com/de/privacy/
Data Processing Agreementhttps://wordpress.com/support/data-processing-agreements/
Third-Country Data Transfer BasisData Privacy Framework (DPF), Standard Contractual Clauses (provided by service provider)

Use of Cookies

Cookie Definition and Purpose

“Cookies” are functions that store information on user devices and read from them. Cookies serve various purposes, including functionality, security, user comfort, and visitor flow analysis. We use cookies in accordance with legal requirements and obtain user consent where required.

Where consent is not necessary, we rely on legitimate interests when storing and reading information is essential to provide explicitly requested content and functionality, such as storing settings and ensuring online service functionality and security.

Legal Basis

Whether we process personal data through cookies depends on consent. With consent, consent serves as the legal basis. Without consent, we rely on legitimate interests described below and in the context of each service.

Consent Can Be Withdrawn

Users may revoke their consent at any time through privacy settings in their browser or through our cookie management interface.

Cookie Storage Duration

Cookie TypeDescription
Temporary Cookies (Session Cookies)Deleted at the latest when the user leaves the online service and closes their device (browser or mobile app)
Permanent CookiesRemain stored after the device is closed, allowing login status to be saved and preferred content to be displayed on return visits. May be used for reach measurement with a storage duration up to two years unless otherwise specified

Withdrawal and Opt-Out Options

Users may revoke their consent at any time and may object to processing in accordance with legal requirements, including through privacy settings in their browser.


Essential Cookies

Essential cookies enable basic functions and are necessary for proper website operation.

Cookie IDPurposeDuration
wpconsent_preferencesStores user cookie consent preferences30 days

Comments Cookies

These cookies are needed for adding comments on this website.

Cookie IDPurposeDuration
comment_authorTracks the user across multiple sessionsSession
comment_author_emailTracks the user across multiple sessionsSession
comment_author_urlTracks the user across multiple sessionsSession

Data Types: Meta, communication, and procedural data (IP addresses, timestamps, identification numbers, involved persons)

Affected Persons: Users (website visitors, online service users)

Legal Basis: Legitimate interests (Article 6(1)(f) GDPR); Consent (Article 6(1)(a) GDPR)

Cookie Data Processing Based on Consent

We use a consent management solution where user consent is obtained for cookie use and related procedures and providers mentioned in the consent management solution. This process serves to obtain, record, manage, and revoke consent, particularly regarding cookies and similar technologies for storing, reading, and processing information on user devices.

Through this process, we obtain user consent for cookie use and associated information processing, including specific processing and providers mentioned in the consent management procedure. Users have the ability to manage and revoke their consent.